A breach, ransomware attack or fake online profile can damage customer confidence before you know what to say. Cyber insurance may fund technical recovery, but it may leave urgent communications subject to limits, approval rules or exclusions. In the first 72 hours, unclear messages can deepen disruption.
After a cyber incident, PR & reputational protection can fund approved crisis communications, specialist support and customer notification. It does not cover every loss of trust. Check your policy's payments, limits, exclusions and activation rules. This is general information, not insurance or legal advice.
Cyber cover pays repair costs, not lost trust
Cyber insurance normally pays defined reputation protection expenses. These are costs for repairing communications after a covered cyber event. It is not a blank cheque for damaged goodwill. A £1 million cyber policy may allow only £10,000 to £50,000 for crisis communications. The PR sub-limit matters as much as the headline limit.
Reputational harm and repair are different
Reputational harm means lost trust, goodwill or business value. Reputational repair means approved work that explains an incident and limits further harm. A policy may fund advisers, customer emails, media handling and call centres. It may not fund a lower valuation, lost future contracts or a general drop in online sentiment.
| Term | What it means | Usually insured? |
|---|
| Reputational harm | Lost trust, goodwill or business value | Usually no |
| Reputational repair | Approved work to manage public concern | Often, if triggered |
| Crisis communications | Messages for customers, staff and media | Often within a PR limit |
| Business interruption | Lost income while systems cannot trade | Separate policy section |
A covered incident must start the claim
A coverage trigger is the event that starts the insurer's duty to consider a claim. Common triggers include ransomware, a data breach, cyber extortion or network security failure. PR protection may not apply if publicity has no insured cyber cause.
A breach involving personal data may need an assessment under UK data protection law. The Information Commissioner's Office expects firms to assess risks to people's rights and freedoms.
Policy exclusions can matter as much as the PR expense limit. Cyber insurance does not normally pay for lost share value, business value or goodwill. This remains true when a cyber incident causes reputational harm.
It may also exclude lost intellectual property and known circumstances that existed before cover began. Deliberate or dishonest acts may also fall outside cover. Costs spent without the insurer's consent may be excluded.
For example, a firm may know customer data was exposed before renewal but report the event only after buying cover. The insurer may treat this as a pre-existing circumstance.
Read exclusions alongside endorsements before relying on crisis communications cover.
Compare cyber PR cover with public liability
Cyber PR cover responds to a digital incident. Public liability insurance addresses third-party injury or property damage claims. Public liability will not normally fund a specialist to explain ransomware to customers. Cyber cover may fund this, subject to its wording, approval rules and PR expense limit.
Insurers may appoint forensic investigators, solicitors and PR consultants after an attack. This incident response can include notification advice, customer updates and call handling. The National Cyber Security Centre resources can help SMEs prepare contact lists, backup plans and reporting routes.
Online abuse may sit outside cyber cover
Fake reviews, misinformation campaigns and non-cyber social media backlash often fall outside standard cyber insurance. Impersonation or deepfakes may be covered only with social engineering fraud, identity fraud or defined security event wording.
An illustrative comparison follows. A breach exposing 800 client records may trigger notification and PR support. Ransomware stopping trade for 3 days may also trigger business interruption. A deepfake invoice scam may need social engineering fraud cover. Two hundred fake reviews may receive no funding unless the policy says so.
The financial impact can differ sharply by scenario. A breach involving 2,000 customers might create £6,000 of notification costs. It might also create £8,000 of legal review costs.
Customer communications might cost £12,000, while PR support might cost £15,000. That uses £41,000 before any forensic costs.
Ransomware can prevent online trading for five days and may add business interruption losses. A deepfake may require fast media monitoring and customer reassurance.
That deepfake may not trigger cover. Cover may require a defined network security failure or fraud event. The error many firms make is assuming online harm always means insured cyber harm.
By contrast, 300 fake reviews may cost £5,000 in agency and legal support. They may still remain uninsured under a standard cyber policy. Test each policy sub-limit against realistic response costs.
Check triggers, excesses and PR limits before renewal
A suitable policy matches your likely incident with its trigger, PR sub-limit, retention and supplier rules. A retention, often called an excess, is what you pay before the insurer pays. Check the wording, endorsements and schedule. These control the decision, not summaries or verbal assurances.
Review these six policy points
Use this checklist when comparing cyber insurance quotes or preparing for renewal.
- Trigger: Confirm whether a data breach, ransomware event, network failure or cyber extortion is required.
- PR sub-limit: Record the separate amount available for reputation protection expenses.
- Retention: Check what you must pay and whether it applies to each cover section.
- Provider panel: Ask if you must use the insurer's approved PR, legal or forensic firms.
- Indemnity period: Check how long business interruption income is covered, often between 12 and 24 months.
- Income calculation: Ask how the insurer calculates lost profit, saved costs and required evidence.
Prioritise cover by customer exposure
Professional firms, online retailers, healthcare suppliers and finance-related businesses may need stronger communications support. They often hold personal, payment or sensitive information. Customer concentration also matters.
A firm with three major buyers can face greater trust risk than a firm with thousands of small customers.
A simple sector view can help set priorities. Online retailers and subscription firms should assess customer communications and business interruption. An unavailable website can quickly affect orders and trust.
Healthcare suppliers, legal practices and financial services firms may value notification, legal advice and crisis communications because they handle sensitive information. Manufacturers and logistics firms may need stronger interruption protection when network failure stops production or dispatch.
Small firms with a few major clients should also consider higher PR limits. Lost confidence from one buyer can cause serious harm.
Firms exposed to fake reviews, impersonation or misinformation should check separate extensions. Look for digital reputation, media liability or fraud cover. Do not assume cyber insurance will respond.
Use the first 72 hours to protect trust
The first 72 hours should follow a simple sequence. Verify facts and preserve evidence in the first 24 hours. Notify the insurer and affected parties, when needed, by 48 hours. Give consistent recovery updates by 72 hours.
Isolate affected systems if safe. Preserve logs. Do not guess what attackers took.
Keep one approved message source
One named spokesperson and one approved message source reduce confusion. Customers need plain information about what happened and what you know. They also need to know what you are doing and where they can get help.
Avoid technical detail that helps attackers. Avoid claims that may later prove wrong.
Unapproved PR costs can be excluded, even when the incident is covered. Call the insurer's hotline before hiring an agency. Ask for written approval and confirm the sub-limit and appointed provider.
Immediate spending may be needed to prevent physical harm or meet a clear legal duty. Record why it was urgent, then contact the insurer as soon as possible.
During a live attack, speed still matters. Act on urgent safety and legal needs while keeping a clear record of decisions and costs.
This guidance is less relevant when reputational harm is unrelated to a cyber event. Examples include poor service, product safety, employment disputes or a traditional media controversy. It cannot confirm cover under a particular policy. The wording, endorsements and insurer's claim decision control what is insured.
Questions & answers
Does cyber insurance cover reputational damage?
It can fund approved reputation protection expenses after a covered cyber incident. It does not usually pay for every loss of goodwill, customer confidence, valuation or future sales.
Does public liability pay for cyber PR support?
Usually no. Public liability covers third-party injury or property damage claims. Cyber insurance is more likely to fund crisis communications after a breach or ransomware event.
How much PR cover should a small business buy?
It depends on customer numbers, sector and likely notification costs. PR sub-limits often range from £10,000 to £50,000. Check if call handling, legal review and customer letters are included.
Are fake reviews covered by cyber insurance?
Usually not, unless they follow a defined covered cyber event. Wider online reputation wording may also cover them. A fake-review dispute without hacking, fraud or network failure may fall outside cover.
Make the insurer call before the public statement
The best reputational protection starts before an incident. Keep a tested contact list, a clear reporting route and policy wording that pays for needed support. Confirm the hotline, PR trigger, sub-limit and approval process before renewal.
Keep any first public statement factual, short and insurer-approved.